Atlassian Administrator Expert
Workflows
User Provisioning
- 1. Create user account: INLINECODE0
- REST API:
POST /rest/api/3/user with
{"emailAddress": "...", "displayName": "...","products": [...]}
- 2. Add to appropriate groups: INLINECODE3
- Assign product access (Jira, Confluence) via INLINECODE4
- Configure default permissions per group scheme
- Send welcome email with onboarding info
- NOTIFY: Relevant team leads of new member
- VERIFY: Confirm user appears active at
admin.atlassian.com/o/{orgId}/users and can log in
User Deprovisioning
- 1. CRITICAL: Audit user's owned content and tickets
- Jira:
GET /rest/api/3/search?jql=assignee={accountId} to find open issues
- Confluence:
GET /wiki/rest/api/user/{accountId}/property to find owned spaces/pages
- 2. Reassign ownership of:
- Jira projects:
Project settings > People > Change lead
- Confluence spaces:
Space settings > Overview > Edit space details
- Open issues: bulk reassign via
Jira > Issues > Bulk change
- Filters and dashboards: transfer via
User management > [user] > Managed content
- 3. Remove from all groups: INLINECODE12
- Revoke product access
- Deactivate account: INLINECODE13
- REST API:
DELETE /rest/api/3/user?accountId={accountId}
- 6. VERIFY: Confirm
GET /rest/api/3/user?accountId={accountId} returns INLINECODE16 - Document deprovisioning in audit log
- USE: Jira Expert to reassign any remaining issues
Group Management
- 1. Create groups: INLINECODE17
- REST API:
POST /rest/api/3/group with
{"name": "..."}
- Structure by: Teams (engineering, product, sales), Roles (admins, users, viewers), Projects (project-alpha-team)
- 2. Define group purpose and membership criteria (document in Confluence)
- Assign default permissions per group
- Add users to appropriate groups
- VERIFY: Confirm group members via INLINECODE20
- Regular review and cleanup (quarterly)
- USE: Confluence Expert to document group structure
Permission Scheme Design
Jira Permission Schemes (
Jira Settings > Issues > Permission Schemes):
- - Public Project: All users can view, members can edit
- Team Project: Team members full access, stakeholders view
- Restricted Project: Named individuals only
- Admin Project: Admins only
Confluence Permission Schemes (Confluence Admin > Space permissions):
- - Public Space: All users view, space members edit
- Team Space: Team-specific access
- Personal Space: Individual user only
- Restricted Space: Named individuals and groups
Best Practices:
- - Use groups, not individual permissions
- Principle of least privilege
- Regular permission audits
- Document permission rationale
SSO Configuration
- 1. Choose identity provider (Okta, Azure AD, Google)
- Configure SAML settings: INLINECODE23
- Set Entity ID, ACS URL, and X.509 certificate from IdP
- 3. Test SSO with admin account (keep password login active during test)
- Test with regular user account
- Enable SSO for organization
- Enforce SSO: INLINECODE24
- Configure SCIM for auto-provisioning: INLINECODE25
- VERIFY: Confirm SSO flow succeeds and audit logs show
saml.login.success events - Monitor SSO logs: INLINECODE27
Marketplace App Management
- 1. Evaluate app need and security: check vendor's security self-assessment at INLINECODE28
- Review vendor security documentation (penetration test reports, SOC 2)
- Test app in sandbox environment
- Purchase or request trial: INLINECODE29
- Install app: INLINECODE30
- Configure app settings per vendor documentation
- Train users on app usage
- VERIFY: Confirm app appears in
GET /rest/plugins/1.0/ and health check passes - Monitor app performance and usage; review annually for continued need
System Performance Optimization
Jira (
Jira Settings > System):
- - Archive old projects: INLINECODE33
- Reindex: INLINECODE34
- Clean up unused workflows and schemes: INLINECODE35
- Monitor queue/thread counts: INLINECODE36
Confluence (Confluence Admin > Configuration):
- - Archive inactive spaces: INLINECODE38
- Remove orphaned pages: INLINECODE39
- Monitor index and cache: INLINECODE40
Monitoring Cadence:
- - Daily health checks: INLINECODE41
- Weekly performance reports
- Monthly capacity planning
- Quarterly optimization reviews
Integration Setup
Common Integrations:
- - Slack:
Jira Settings > Apps > Slack integration — notifications for Jira and Confluence - GitHub/Bitbucket:
Jira Settings > Apps > DVCS accounts — link commits to issues - Microsoft Teams: INLINECODE44
- Zoom: Available via Marketplace app INLINECODE45
- Salesforce: Via Marketplace app INLINECODE46
Configuration Steps:
- 1. Review integration requirements and OAuth scopes needed
- Configure OAuth or API authentication (store tokens in secure vault, not plain text)
- Map fields and data flows
- Test integration thoroughly with sample data
- Document configuration in Confluence runbook
- Train users on integration features
- VERIFY: Confirm webhook delivery via INLINECODE47
- Monitor integration health via app-specific dashboards
Global Configuration
Jira Global Settings (Jira Settings > Issues)
Issue Types: Create and manage org-wide issue types; define issue type schemes; standardize across projects
Workflows: Create global workflow templates via
Workflows > Add workflow; manage workflow schemes
Custom Fields: Create org-wide custom fields at
Custom fields > Add custom field; manage field configurations and context
Notification Schemes: Configure default notification rules; create custom notification schemes; manage email templates
Confluence Global Settings (Confluence Admin)
Blueprints & Templates: Create org-wide templates at
Configuration > Global Templates and Blueprints; manage blueprint availability
Themes & Appearance: Configure org branding at
Configuration > Themes; customize logos and colors
Macros: Enable/disable macros at
Configuration > Macro usage; configure macro permissions
Security Settings (admin.atlassian.com > Security)
Authentication:
- - Password policies: INLINECODE56
- Session timeout: INLINECODE57
- API token management: INLINECODE58
Data Residency: Configure data location at INLINECODE59
Audit Logs: admin.atlassian.com > Security > Audit log
- - Enable comprehensive logging; export via INLINECODE61
- Retain per policy (minimum 7 years for SOC 2/GDPR compliance)
Governance & Policies
Access Governance
- - Quarterly review of all user access: INLINECODE62
- Verify user roles and permissions; remove inactive users
- Limit org admins to 2–3 individuals; audit admin actions monthly
- Require MFA for all admins: INLINECODE63
Naming Conventions
Jira: Project keys 3–4 uppercase letters (PROJ, WEB); issue types Title Case; custom fields prefixed (CF: Story Points)
Confluence: Spaces use Team/Project prefix (TEAM: Engineering); pages descriptive and consistent; labels lowercase, hyphen-separated
Change Management
Major Changes: Announce 2 weeks in advance; test in sandbox; create rollback plan; execute during off-peak; post-implementation review
Minor Changes: Announce 48 hours in advance; document in change log; monitor for issues
Disaster Recovery
Backup Strategy
Jira & Confluence: Daily automated backups; weekly manual verification; 30-day retention; offsite storage
- - Trigger manual backup:
Jira Settings > System > Backup system / INLINECODE65
Recovery Testing: Quarterly recovery drills; document procedures; measure RTO and RPO
Incident Response
Severity Levels:
- - P1 (Critical): System down — respond in 15 min
- P2 (High): Major feature broken — respond in 1 hour
- P3 (Medium): Minor issue — respond in 4 hours
- P4 (Low): Enhancement — respond in 24 hours
Response Steps:
- 1. Acknowledge and log incident
- Assess impact and severity
- Communicate status to stakeholders
- Investigate root cause (check
admin.atlassian.com > Products > [product] > Health and Atlassian Status Page) - Implement fix
- VERIFY: Confirm resolution via affected user test and health check
- Post-mortem and lessons learned
Metrics & Reporting
System Health: Active users (daily/weekly/monthly), storage utilization, API rate limits, integration health, response times
- - Export via:
GET /admin/v1/orgs/{orgId}/users for user counts; product-specific analytics dashboards
Usage Analytics: Most active projects/spaces, content creation trends, user engagement, search patterns
Compliance Metrics: User access review completion, security audit findings, failed login attempts, API token usage
Decision Framework & Handoff Protocols
Escalate to Atlassian Support: System outage, performance degradation org-wide, data loss/corruption, license/billing issues, complex migrations
Delegate to Product Experts:
- - Jira Expert: Project-specific configuration
- Confluence Expert: Space-specific settings
- Scrum Master: Team workflow needs
- Senior PM: Strategic planning input
Involve Security Team: Security incidents, unusual access patterns, compliance audit preparation, new integration security review
TO Jira Expert: New global workflows, custom fields, permission schemes, or automation capabilities available
TO Confluence Expert: New global templates, space permission schemes, blueprints, or macros configured
TO Senior PM: Usage analytics, capacity planning insights, cost optimization, security compliance status
TO Scrum Master: Team access provisioned, board configuration options, automation rules, integrations enabled
FROM All Roles: User access requests, permission changes, app installation requests, configuration support, incident reports
Atlassian MCP Integration
Primary Tools: Jira MCP, Confluence MCP
Admin Operations:
- - User and group management via API
- Bulk permission updates
- Configuration audits
- Usage reporting
- System health monitoring
- Automated compliance checks
Integration Points:
- - Support all roles with admin capabilities
- Enable Jira Expert with global configurations
- Provide Confluence Expert with template management
- Ensure Senior PM has visibility into org health
- Enable Scrum Master with team provisioning
Atlassian 管理员专家
工作流程
用户配置
- 1. 创建用户账户:admin.atlassian.com > 用户管理 > 邀请用户
- REST API:POST /rest/api/3/user,参数为 {emailAddress: ..., displayName: ...,products: [...]}
- 2. 添加到相应群组:admin.atlassian.com > 用户管理 > 群组 > [群组] > 添加成员
- 通过 admin.atlassian.com > 产品 > [产品] > 访问权限 分配产品访问权限(Jira、Confluence)
- 按群组方案配置默认权限
- 发送包含入职信息的欢迎邮件
- 通知:相关团队负责人新成员加入
- 验证:在 admin.atlassian.com/o/{orgId}/users 确认用户显示为活跃状态且能够登录
用户注销
- 1. 关键:审计用户拥有的内容和工单
- Jira:GET /rest/api/3/search?jql=assignee={accountId} 查找未关闭问题
- Confluence:GET /wiki/rest/api/user/{accountId}/property 查找拥有的空间/页面
- 2. 重新分配所有权:
- Jira项目:项目设置 > 人员 > 更改负责人
- Confluence空间:空间设置 > 概览 > 编辑空间详情
- 未关闭问题:通过 Jira > 问题 > 批量更改 批量重新分配
- 筛选器和仪表板:通过 用户管理 > [用户] > 管理内容 转移
- 3. 从所有群组中移除:admin.atlassian.com > 用户管理 > [用户] > 群组
- 撤销产品访问权限
- 停用账户:admin.atlassian.com > 用户管理 > [用户] > 停用
- REST API:DELETE /rest/api/3/user?accountId={accountId}
- 6. 验证:确认 GET /rest/api/3/user?accountId={accountId} 返回 active: false
- 在审计日志中记录注销操作
- 使用:Jira专家重新分配任何剩余问题
群组管理
- 1. 创建群组:admin.atlassian.com > 用户管理 > 群组 > 创建群组
- REST API:POST /rest/api/3/group,参数为 {name: ...}
- 按以下结构组织:团队(工程、产品、销售)、角色(管理员、用户、查看者)、项目(project-alpha-team)
- 2. 定义群组目的和成员资格标准(在Confluence中记录)
- 为每个群组分配默认权限
- 将用户添加到相应群组
- 验证:通过 GET /rest/api/3/group/member?groupName={name} 确认群组成员
- 定期审查和清理(每季度)
- 使用:Confluence专家记录群组结构
权限方案设计
Jira权限方案(Jira设置 > 问题 > 权限方案):
- - 公共项目:所有用户可查看,成员可编辑
- 团队项目:团队成员完全访问,利益相关者可查看
- 受限项目:仅指定个人
- 管理项目:仅管理员
Confluence权限方案(Confluence管理 > 空间权限):
- - 公共空间:所有用户可查看,空间成员可编辑
- 团队空间:团队特定访问权限
- 个人空间:仅单个用户
- 受限空间:指定个人和群组
最佳实践:
- - 使用群组,而非个人权限
- 最小权限原则
- 定期权限审计
- 记录权限理由
SSO配置
- 1. 选择身份提供商(Okta、Azure AD、Google)
- 配置SAML设置:admin.atlassian.com > 安全 > SAML单点登录 > 添加SAML配置
- 设置来自IdP的实体ID、ACS URL和X.509证书
- 3. 使用管理员账户测试SSO(测试期间保持密码登录激活)
- 使用普通用户账户测试
- 为组织启用SSO
- 强制执行SSO:admin.atlassian.com > 安全 > 身份验证策略 > 强制执行SSO
- 配置SCIM用于自动配置:admin.atlassian.com > 用户配置 > [IdP] > 启用SCIM
- 验证:确认SSO流程成功,审计日志显示 saml.login.success 事件
- 监控SSO日志:admin.atlassian.com > 安全 > 审计日志 > 筛选:SSO
Marketplace应用管理
- 1. 评估应用需求和安全性:在 marketplace.atlassian.com 查看供应商的安全自我评估
- 审查供应商安全文档(渗透测试报告、SOC 2)
- 在沙盒环境中测试应用
- 购买或申请试用:admin.atlassian.com > 计费 > 管理订阅
- 安装应用:admin.atlassian.com > 产品 > [产品] > 应用 > 查找新应用
- 按供应商文档配置应用设置
- 培训用户使用应用
- 验证:确认应用出现在 GET /rest/plugins/1.0/ 中且健康检查通过
- 监控应用性能和用量;每年审查持续需求
系统性能优化
Jira(Jira设置 > 系统):
- - 归档旧项目:项目设置 > 归档项目
- 重新索引:Jira设置 > 系统 > 索引 > 完全重新索引
- 清理未使用的工作流和方案:Jira设置 > 问题 > 工作流
- 监控队列/线程数:Jira设置 > 系统 > 系统信息
Confluence(Confluence管理 > 配置):
- - 归档非活跃空间:空间工具 > 概览 > 归档空间
- 移除孤立页面:Confluence管理 > 孤立页面
- 监控索引和缓存:Confluence管理 > 缓存管理
监控节奏:
- - 每日健康检查:admin.atlassian.com > 产品 > [产品] > 健康
- 每周性能报告
- 每月容量规划
- 每季度优化审查
集成设置
常见集成:
- - Slack:Jira设置 > 应用 > Slack集成 — Jira和Confluence的通知
- GitHub/Bitbucket:Jira设置 > 应用 > DVCS账户 — 将提交链接到问题
- Microsoft Teams:admin.atlassian.com > 应用 > Microsoft Teams
- Zoom:通过Marketplace应用 zoom-for-jira 获取
- Salesforce:通过Marketplace应用 salesforce-connector 获取
配置步骤:
- 1. 审查集成需求和所需的OAuth范围
- 配置OAuth或API认证(将令牌存储在安全保管库中,而非明文)
- 映射字段和数据流
- 使用样本数据彻底测试集成
- 在Confluence运行手册中记录配置
- 培训用户使用集成功能
- 验证:通过 Jira设置 > 系统 > WebHooks > [webhook] > 测试 确认Webhook投递
- 通过特定应用仪表板监控集成健康
全局配置
Jira全局设置(Jira设置 > 问题)
问题类型:创建和管理组织范围的问题类型;定义问题类型方案;跨项目标准化
工作流:通过 工作流 > 添加工作流 创建全局工作流模板;管理工作流方案
自定义字段:在 自定义字段 > 添加自定义字段 创建组织范围的自定义字段;管理字段配置和上下文
通知方案:配置默认通知规则;创建自定义通知方案;管理邮件模板
Confluence全局设置(Confluence管理)
蓝图和模板:在 配置 > 全局模板和蓝图 创建组织范围的模板;管理蓝图可用性
主题和外观:在 配置 > 主题 配置组织品牌;自定义徽标和颜色
宏:在 配置 > 宏使用 启用/禁用宏;配置宏权限
安全设置(admin.atlassian.com > 安全)
身份验证:
- - 密码策略:安全 > 身份验证策略 > 编辑
- 会话超时:安全 > 会话时长
- API令牌管理:安全 > API令牌控制
数据驻留:在 admin.atlassian.com > 数据驻留 > 固定产品 配置数据位置
审计日志:admin.atlass